PDA

View Full Version : a few weird problems


BlueSite
5-24-05, 04:06 AM
ok...for the record, i am running win xp on a machine with 512mb ram, an amd athlon (not sure the speed), near 3 ghz i believe. umm, i have SP1, downloaded SP2 months ago and couldnt get many programs to work (yahoo messenger, outlook, etc)...and i will paste my hijackthis log below

ive noticed that everytime i turn my computer on, it goes thru the scandisk and ends up deleting all sorts of index entrues and corrupt file attribute records (not tons, maybe 15 total?)...but it does it every time i turn it on which is odd.

when i start the PC up, most of the time, many of the desktop icons take a while to show up. they show up, but they have that generic icon symbol before they actually load fully. instead of URL's with the MS e on them, it has the box with the 3 boxes of color i believe? it takes them about 2 or 3 mins to load sometimes...then again, sometimes it all loads right away, no problems.

next...i noticed that zone alarm wont remember any of my programs all of a sudden. i have to check them all anew to allow them to access the net (browser, winamp, filezilla, etc). that was never a problem before.

my sound card (a creative audigy 2 zs) always reverts back to default settings of no effects and spkr setup as 2.1 when it should be 5.1 i have to gp in everytime i restart and change these settings. never had any of these problems before, and i havent installed or added any hardware or anything, so im confused as to what could be casuing these problems. its anot a big problem, exept the other day when i uninstalled spyware doctor, my pc wouldnt start...it got to the desktop and no icons would show up, nothing...said explorer shut down, had to reboot and it worked. got it started, then it said it didnt find the sound card that went along with my equalizer so it wouldnt work with that...retsrated again, and all was well again. very confusing. anyone have any ideas or any idea of where to start to look?


thanks for any info.
-----------------------------
Logfile of HijackThis v1.99.0
Scan saved at 1:58:08 AM, on 5/24/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE
C:\WINDOWS\System32\CTHELPER.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Creative\MediaSource\Go\CTCMSGo.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\SlimBrowser\sbrowser.exe
C:\Documents and Settings\Joshua Bozeman\Desktop\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SnapFlash Class - {A44CBB0B-C77D-4BF5-87CC-B4EE79AD1B7E} - C:\Program Files\Common Files\justDo\Jd2002.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.d ll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTDVDDET] C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Creative MediaSource Go] C:\Program Files\Creative\MediaSource\Go\CTCMSGo.exe /SCB
O8 - Extra context menu item: Save Flash with Flash Catcher - res://C:\Program Files\Common Files\justDo\IECatcher.DLL/FlashCatcher.htm
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Flash Catcher - {90BAE0EF-F4BF-4FAC-B2EC-2C725C34AF12} - C:\Program Files\Common Files\justDo\IECatcher.DLL
O9 - Extra 'Tools' menuitem: Flash Catcher - {90BAE0EF-F4BF-4FAC-B2EC-2C725C34AF12} - C:\Program Files\Common Files\justDo\IECatcher.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?
O23 - Service: AVG7 Alert Manager Server - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: TrueVector Internet Monitor - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

BlueSite
5-24-05, 04:10 AM
i should also note...sometimes when i do something that takes a lot of my pcs power...the icons will rearrange themselves (well, sometimes, if theyre scattered or ive added a new one, theyll all go into rows, blink off and refresh.) hard to explain, but im sure someone knows what i mean! :)

patrickpawlowsk
5-24-05, 07:56 AM
My professional diagnosis is: Demonic Possession! Seems like it sometimes, doesn't it? Looks like you have a lot of sh..,er...Stuff, running on that box. I am pretty guilty of the same, except for ZoneAlarm. I just use a linksys router and so far have been fine. Anyway, how long has it been since you rebuilt this machine? i.e. reformat & reinstall. I am a big advocate of doing this every year or two. But that is me. There are others who agree, other who don't. If that's not an option for you, you might try the standard tune up routine. I generally go through Add Remove Programs and uninstalling anything that I'm not really using. Then run through all the utilites: AdAware, SpyBot, a full antivirus check clean up any temp files you may find. Clean out the %temp% folder and I usually search the c: driver for *.tmp and then delete whatever it finds. I suppose this could be dangerous but I have never had a problem. The the coup de grāce, the all night, beat this drive back into shape, defrag.

Personally, since I can reformat and reinstall in about 2 hours, and since the R&R is much more thorough than all the hassle above, that's what I normally do.

Also, from what I see of your logfile above. I don't any glaring problems.

Sorry, I realized that this is probably not the answer you are looking for and hopefully someone can chime in with something more specific for you to try.

-pat

YvetteKuhns
5-24-05, 02:21 PM
You have alot of programs running that use alot of resources. I personally do not recommend instant messaging, because it is a source of many problems for viruses. But as long as you keep your antivirus and worm protection updated, you should be okay.

If you use a router with a built-in firewall, you should not require software to do this. Windows XP has firewall software that does not like to work with other firewall software such as Zone Alarm which is particularly picky and annoying. These programs fight each other while your antivirus uses resources. Then you have that annoying Weather Bug that runs in the background, too. That should be removed.

I have SP1, downloaded SP2 months ago and couldnt get many programs to work (yahoo messenger, outlook, etc)

Did you disable the running programs BEFORE you installed SP2? Any Windows updates can change your settings back to the default which is annoying. But if you have other programs running while installing a program, there can be problems. The worst offenders are antivirus, firewall, screen savers, other utilities that are always running or updating like that weather bug.

You may need to uninstall and reinstall the programs that no longer work. I would recommend making a backup of the hard drive, then reformatting if removing and reinstalling doesn't work. But you must disable those programs to reinstall each one. Sorry.


ive noticed that everytime i turn my computer on, it goes thru the scandisk and ends up deleting all sorts of index entrues and corrupt file attribute records (not tons, maybe 15 total?)...but it does it every time i turn it on which is odd.


If scandisk/checkdisk finds corrupt records, you should take note of which ones they are. I do not have mine set to automatically fix errors, so I can notice which files are corrupted. Recently, my Norton Systemworks had some corrupted files. I had to uninstall and reinstall or modify (I forget which) Norton to use it, because it no longer worked.

All the crazy problems and different results when you reboot are usually Windows problems which usually means it must be reinstalled.

BlueSite
5-24-05, 06:58 PM
i forgot to mention...i scanned with spybot s&d, ad aware, avg free, spyware doctor...ran a scan for cool web search, etc. deleted all my windows history and temp files...all my history, cookies, tem internet files folders as well.

i just reformatted this drive (110GB drive, with nearly 60GB used up) about 4 months ago, i guess it was. bought a windows cd rom, because i bought the pc refurbished from tiger direct and all the install files were on a separate drive partition, and that caused problems.

i did go thru not too long ago and delete a bunch of programs i never use....and i dont notice any problems messing up, just windows really. other than start up taking so long, the zone alarm forgetting all the programs and the sound card settings going back to default everytime its turned off or restarted, it runs fine. so, i dont think i want to burn all my stuff to dvds and reinstall just yet.

i do need to try to defrag the hard drive tho
----------------
as for SP2, i did that months ago before i reinstalled with a fresh cd of xp. nothing would connect after using it...i read of problems with certain programs not working but i dont remember what it all said. it was all disabled when i did it tho.

if i were going to use the XP firewall and uninstall zone alarm, the firewall is built into the SP1 cd right? i should have it...i just remember that SP1 doesnt automatically enable it and i cant for the life of me remember where to find it. need to uninstall the yahoo companion files too that hijack this shows...not even sure what those are.

BlueSite
5-24-05, 07:09 PM
ok weird...i uninstalled those yahoo files showing in hijack this, uninstalled them in programs, uninstalled zone alarm and weather bug....restarted and it loaded immediately and the sound card settings were remembered...

and it didnt run scan disk this time either.

no way it could have been that easy

i searched google and found out how to enable xp firewall...went in and its already checked to protect the computer. does the built in firewall show anything to let you know its running, add programs to allow to access the net, etc? because ive never seen anything pop up, and its checked right now to be enabled. i thought i used it before and remember an interface of some sort...?

YvetteKuhns
5-24-05, 08:54 PM
uninstalled zone alarm and weather bug....restarted and it loaded immediately and the sound card settings were remembered...
no way it could have been that easy


I have dealt with this problem with other people who did the same thing. Glad it was an easy fix. I usually recommend backups before doing anything drastic in case you are having hard drive failure. I luckily backed up most of my important files before my hard drive died after toasting my CPU.

i searched google and found out how to enable xp firewall...went in and its already checked to protect the computer.

I believe that it is enabled as the default for SP2.

http://www.microsoft.com/windowsxp/using/networking/learnmore/icf.mspx

Yes, it is.

does the built in firewall show anything to let you know its running, add programs to allow to access the net

It's a Windows product, so..... :D
http://techrepublic.com.com/5100-1035_11-5305934.html
Ah, this may help.

http://support.microsoft.com/default.aspx?kbid=842242
http://news.techwhack.com/593/xp-firewall-fix/
More fun to expect! :rolleyes:

My experience with XP was short-lived. I instantly got the Blaster and another worm and removed XP. Same with 2000 Pro, so I went back to 98 SE. I will have to update some time, but then some of my old scanners and other stuff won't have drivers. :rolleyes:

fluKe
5-27-05, 08:41 AM
I very strongly recommend putting Zone Alarm (or Kerio) back on your PC.

Software firewalls do not use a lot of resources (on my PC zone alarm uses ~4Mb of RAM total). The firewall supplied with windows is not any good. Apart from being ineffective compared to a full blown software firewall like ZoneAlarm it simply isn't that good.

Also, don't rely on your routers firewall!! Yes it may stop most problems but many routers do not protect against all lines of attack and there are often exploits found in generic routers (eg. linkysys belkin etc.) which make them an easy target for people to get through if you are not running a software firewall. It is always better to have an extra layer of protection. And remember your routers firewall won't protect you from internal attack (if your on a non-home network).

Also the windows firewall probably uses almost as many resources.

Make sure you don't remove your AV software either, that is suicide.



As for the blaster worm - download the administrative updates that deal with it (or better yet SP2) and once you have installed XP before going online install the service pack/updates. And better yet also install a firewall. Going online with no firewall with a fresh install of XP is asking for trouble!

YvetteKuhns
5-27-05, 10:59 AM
I agree with fluKe that the Windows firewall stinks, but you need to use one. I would disable Windows firewall and use another firewall. You just can't have two SOFTWARE firewalls running simultaneously. I simply was trying to diagnose your problem and didn't want you to go online without any protection.

Zone Alarm can behave strangely and not work well with Norton software. The router firewall does not block all worms and Trojan Horses, but I use Norton Systemworks which has antivirus and worm protection. There have been worms trying to get to my system through FileZilla whenever I use that program!

I got the Blaster worm, because I was too stupid or lazy to remove the cable connection while reinstalling Windows. :rolleyes: I didn't have a chance to install protection and the router firewall did not stop it.

fluKe
5-29-05, 07:15 AM
I got the Blaster worm, because I was too stupid or lazy to remove the cable connection while reinstalling Windows. :rolleyes: I didn't have a chance to install protection and the router firewall did not stop it.

I have done that myself ;) It can be removed though by getting a hold of a removal tool from the net (by using another computer).


If it was a choice between ZA or Norton I would take Norton off... infact I took a brand new fully licensed version of Norton off my mum's new laptop and replaced it with NOD32 and Zone Alarm as soon as it arrived. Just my opinion but I think Norton is bloated and pretty pants ;) But don't let that stop you using it, people always get elitist about whatever AV/FW software they are using :)

linnetwoods
5-29-05, 10:13 AM
My experience with XP was short-lived. I instantly got the Blaster and another worm and removed XP. Same with 2000 Pro, so I went back to 98 SE. I will have to update some time, but then some of my old scanners and other stuff won't have drivers. :rolleyes:

Interesting to see how many of us have gone the same route - I am hoping that it will never be necessary to go back to XP - I can see no reason why one should have to in the forseeable future and, by the time it becomes impossible to refuse, I guess all our old scanners etc., will have died natural deaths anyway. :D

YvetteKuhns
5-29-05, 11:32 AM
Just my opinion but I think Norton is bloated and pretty pants

The latest version is even more bloated and uses even more resources. You need enough RAM to use it. I love the Norton programs and Zone Alarm was such a pain in the butt for me. But I have to agree with you.

It can be removed though by getting a hold of a removal tool from the net (by using another computer).

Been there, done that. I just got upset and I am not a big fan of Windows, so throwing those cds like frisbees just make me feel better somehow. I am stuck using Windows so I can use programs like Photoshop and all my devices that do not have driver support for Linux. :rolleyes:

fluKe
5-31-05, 12:01 AM
I'm not pro-windows or pro-linux... I think Windows wins hands down on ease of use and compatibility but linux wins easily on security, customisation etc. I guess in some ways if linux had been in as wide scale use as it is nowadays back when Windows was first released there wouldn't be the market domination that there now is by Microsoft.

However that's a whole other discussion :)


I too enjoy throwing certain CD's accross the room - pieces of hardware is even more fun ;)

YvetteKuhns
5-31-05, 11:40 AM
I too enjoy throwing certain CD's accross the room - pieces of hardware is even more fun

Yes, I have to agree. Of course, you wouldn't want to be around when I throw a big old monitor off the front porch. That could hurt.

Some people shoot clay disks for sport, but if I had a gun... no, that would be too scary. :D My husband keeps the guns out of my reach. I get a bad temper sometimes. ;)

linnetwoods
5-31-05, 04:40 PM
Yachties string dead CDs up (alongside uninvited boarders...) to flutter in the wind and scare the seagulls into dumping their cargo on someone else's decks...

My husband tried dropping my laptop once. Once. :D